看板FB_security
標 題Re: OpenSSL static analysis, was: De Raadt + FBSD + OpenSSH + hole?
發信站NCTU CS FreeBSD Server (Wed Apr 23 17:57:49 2014)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
On 23 April 2014 02:12, Ronald F. Guilmette <
[email protected]> wrote:
>
> In message <[email protected]>,
> Mark Andrews <[email protected]> wrote:
>
>>As for the number of CLANG analysis warnings. Clang has false
>>positives
>
> Please define your terms.
>
> I do imagine that the truth or falsehood of your assertion may depend
> quite substantally on what one does or does not consider a "false
> positive" in this context.
>
>>some of which are impossible to remove regardless of how
>>you recode the section...
>
> I, for one, would dearly love to see one or more concrete examples
> which purport to support the above assertion (of which I am dubious).
So try wading through the morass of false positives yourself and
discover what a joy it is for yourself.
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"